CVE-2020-11989
CRITICALApache Shiro < 1.5.3 - Authentication Bypass via Spring Dynamic Controllers
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2020-11989. PoCs published by JAckLosingHeart, cuijiung, HYWZ36.
AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2020-11989, demonstrating an authentication bypass vulnerability in Apache Shiro. The code includes a Spring Boot application with Shiro configuration, a custom realm, and a login controller that can be used to test the vulnerability.
Description
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Exploits (3)
This repository contains a functional proof-of-concept for CVE-2020-11989, demonstrating an authentication bypass vulnerability in Apache Shiro. The code includes a Spring Boot application with Shiro configuration, a custom realm, and a login controller that can be used to test the vulnerability.
This repository contains a basic Apache Shiro Spring Boot application with a custom realm for authentication, but it does not include any exploit code or demonstration of CVE-2020-11989. It appears to be a stub or educational example rather than a functional PoC.
This repository contains a proof-of-concept for CVE-2020-11989, demonstrating an authentication bypass vulnerability in Apache Shiro. The code includes a Spring Boot application with Shiro configuration, showcasing how improper configuration can lead to unauthorized access.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H